Trojan

What is “Trojan:Win32/Dostre.CA!MTB”?

Malware Removal

The Trojan:Win32/Dostre.CA!MTB is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Trojan:Win32/Dostre.CA!MTB virus can do?

  • Behavioural detection: Executable code extraction – unpacking
  • Yara rule detections observed from a process memory dump/dropped files/CAPE
  • A process attempted to delay the analysis task.
  • Dynamic (imported) function loading detected
  • Performs HTTP requests potentially not found in PCAP.
  • HTTPS urls from behavior.
  • Enumerates running processes
  • Reads data out of its own binary image
  • Manipulates data from or to the Recycle Bin
  • CAPE extracted potentially suspicious content
  • Unconventionial binary language: Chinese (Simplified)
  • Unconventionial language used in binary resources: Chinese (Simplified)
  • Authenticode signature is invalid
  • Queries information on disks, possibly for anti-virtualization
  • Steals private information from local Internet browsers
  • Network activity contains more than one unique useragent.
  • Collects information about installed applications
  • CAPE detected the WinDealer malware family
  • Checks the CPU name from registry, possibly for anti-virtualization
  • Attempts to modify proxy settings

How to determine Trojan:Win32/Dostre.CA!MTB?


File Info:

name: 2A0427620AE4110F607F.mlw
path: /opt/CAPEv2/storage/binaries/0c64a2d0b25b53de20c665e7d2a04ab990bf25c68a759f4bcc40ad06481d8859
crc32: B7C17BC9
md5: 2a0427620ae4110f607fdd575b838607
sha1: 2dc6e903a8ccc9102d1498ceca7f3382d2b60866
sha256: 0c64a2d0b25b53de20c665e7d2a04ab990bf25c68a759f4bcc40ad06481d8859
sha512: 1258372fb85a62d5eea0499180ddd16c56a4eadbd3d1d739b405c102820bbdc658baef019691f29e98a000180fa07b6856f132ac2ee3eb4fcf7de5beb7f09d36
ssdeep: 3072:n8Cq4Dwh4Yy1Ts/CQBLrjSUiyM4ykU8Up1p0V9QKnj0GusZmAjeQWc+sPXcr+TbP:siSgyBTqp1pE9KGDZZd3bcr+s80ihO
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T184846AB2B910C879DAD195B0DFDEE8E53BB2FC685D1C191E6A32772D4931EA5090C0EC
sha3_384: c971a20f08a9a7df4ec24e546a29fc48640ef1a456367a22c00617028ca6df6f98289d56facb1d61be6b2df10e4c790f
ep_bytes: 558bec6aff687034400068b621400064
timestamp: 2018-05-24 01:56:53

Version Info:

CompanyName:
FileDescription: RunResDll Microsoft 基础类应用程序
FileVersion: 1, 0, 0, 1
InternalName: RunResDll
LegalCopyright: 版权所有 (C) 2018
LegalTrademarks:
OriginalFilename: RunResDll.EXE
ProductName: RunResDll 应用程序
ProductVersion: 1, 0, 0, 1
Translation: 0x0804 0x04b0

Trojan:Win32/Dostre.CA!MTB also known as:

BkavW32.AIDetect.malware2
LionicTrojan.Win32.Agent.4!c
Elasticmalicious (high confidence)
MicroWorld-eScanTrojan.GenericKDZ.83549
FireEyeGeneric.mg.2a0427620ae4110f
CAT-QuickHealTrojan.GenericRI.S23839443
ALYacTrojan.GenericKDZ.83549
CylanceUnsafe
SangforTrojan.Win32.Save.a
K7AntiVirusTrojan ( 0054e0a31 )
AlibabaTrojan:Win32/Kryptik.ece72156
K7GWTrojan ( 0054e0a31 )
CrowdStrikewin/malicious_confidence_100% (W)
BitDefenderThetaGen:NN.ZexaF.34212.yq0@aeatDvbb
CyrenW32/Zusy.CW.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GHFL
TrendMicro-HouseCallTROJ_GEN.R002C0PB422
Paloaltogeneric.ml
KasperskyTrojan.Win32.Agent.qwidcl
BitDefenderTrojan.GenericKDZ.83549
APEXMalicious
TencentMalware.Win32.Gencirc.10b1fe67
Ad-AwareTrojan.GenericKDZ.83549
SophosML/PE-A + Troj/Krypt-FM
ComodoWorm.Win32.Prux.A@4q442u
DrWebTrojan.PWS.Siggen2.3725
TrendMicroTROJ_GEN.R002C0PB422
McAfee-GW-EditionTrojan-FPZA!2A0427620AE4
EmsisoftTrojan.GenericKDZ.83549 (B)
IkarusTrojan.Crypt
GDataTrojan.GenericKDZ.83549
JiangminTrojan.Agent.bwin
AviraHEUR/AGEN.1219715
MAXmalware (ai score=88)
Antiy-AVLTrojan/Generic.ASMalwS.26900A4
MicrosoftTrojan:Win32/Dostre.CA!MTB
CynetMalicious (score: 100)
AhnLab-V3Trojan/Win.Generic.R419093
Acronissuspicious
McAfeeTrojan-FPZA!2A0427620AE4
TACHYONTrojan/W32.Agent.393216.AQA
VBA32Trojan.Fuerboos
MalwarebytesMalware.AI.1848744155
AvastWin32:Trojan-gen
RisingTrojan.Kryptik!8.8 (CLOUD)
YandexTrojan.GenAsa!wOfcMPeEaoo
SentinelOneStatic AI – Suspicious PE
FortinetW32/Kryptik.GHFL!tr
AVGWin32:Trojan-gen
PandaTrj/GdSda.A

How to remove Trojan:Win32/Dostre.CA!MTB?

Trojan:Win32/Dostre.CA!MTB removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment